RULE(RULE ID:337832)

Rule General Information
Release Date: 2024-03-05
Rule Name: Yonyou GRP-U8 SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou GRP-U8 administrative business financial management software is a new generation of products launched by Yonyou Company focusing on national e-government and based on cloud computing technology. The products before 20230905 series of Yonyou GRP-U8R10 U8Manager B, C, G have SQL injection vulnerabilities. The vulnerability is caused by the bx_historyDataCheck.jsp page not effectively filtering the user input, directly concatenating parameter values into the SQL query statement, resulting in an SQL injection vulnerability.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Refer to the announcement or patch by the vendor: https://pan.yonyou.com/s/gUWlv8QkSsY